Hi @ascha ,
Threat Prevention & ATP provides layered security against threats.
Here's a general overview.
Threat Prevention usually relies on Definitions (AmCore/DAT) & uses GTI lookup to identify malware.
Whereas when Threat Prevention comes across a process with Unknown/low reputation, its forwarded to ATP for monitoring. ATP has its own set of rules to verify if the behavior of the process is malicious.
You can read more about each module in depth in the links below.
Threat Prevention - https://docs.mcafee.com/bundle/endpoint-security-10.6.0-threat-prevention-product-guide-windows/page...
ATP - https://docs.mcafee.com/bundle/endpoint-security-10.7.x-common-product-guide-windows/page/GUID-74E29...
Thanks
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!